Re: unofficial package repository and the bugs system

Jim Pick wrote:
> Fabrizio Polacco <fpolacco@icenet.fi> writes:
> > As default we should have two keys: debian.org and non-us.debian.org
> I don't think that is really necessary if we have the packages signed
> by the maintainers, and distribute a maintainer key ring.  Plus, if we
> do it that way, it is much easier to take a maintainers packages out
> of circulation if he/she violates our trust - just remove their key
> from the keyring.

Users adds the keys we distribute to their own keyrings. Removing one
key from the keyring we distribute isn't enough: it should be revoked
and AFAIK only the "owner" can do that, and it's not likely to happen,
because that is their personal key and they probably want to continue to
use it. People would also get keys from the keyservers, without thinking
that they could be used to validate packages.

I think that the maintainer's signature only certify to Debian that the
package really came from that person (and Debian knowns if he/she is a
trusted maintainer or not), but doesn't certify to users that the
package came from Debian or not.

As several maintainers do, I also upload my packages to an ftp site
that's not under Debian's control. That package could be rejected or the
tester could find there a severe security flaw, and the package won't
find a way to the ftp hierarchy. But a copy, with my signature as a
trusted Debian maintainer, still was available and could have been
downloaded by an unaware user.

No, I think that they should be separate certifications because they
fill separate needs.

